Courseiva

Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question

A team is deploying a Retrieval-Augmented Generation application as a Mosaic AI Agent using `databricks.agents.deploy()`. The agent must query a Vector Search index and a Delta table in Unity Catalog. During testing, the endpoint returns permission errors when accessing those resources, even though the deploying user has access. Which configuration should the engineer apply to resolve this?

⚠ Common exam trap

The trap here is assuming the endpoint inherits the deploying user's permissions, when agent endpoints actually run under a separate service identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a serving credential via a Unity Catalog service principal and grant that principal access to the index and table.

Mosaic AI Agent endpoints execute under a dedicated service identity, not the deploying user's identity, so Unity Catalog resources must explicitly grant that identity access. Configuring a serving credential tied to a service principal and granting it the necessary privileges on the Vector Search index and Delta table lets the agent authenticate at runtime. Token-based workarounds either expire or over-privilege, and Unity Catalog enforcement cannot be disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable Unity Catalog enforcement on the endpoint so it can read resources with the deploying user's identity.

    Why it's wrong here

    There is no supported switch to disable Unity Catalog enforcement for an agent endpoint. Unity Catalog is the governance layer that mediates access to tables and indexes, and bypassing it would break auditability and violate least-privilege requirements. The permission errors stem from the endpoint's identity lacking grants, not from enforcement being enabled, so this does not resolve the failure.

  • ✗

    Grant the deploying user's personal access token to the endpoint and store it in the model signature.

    Why it's wrong here

    Model signatures describe input and output schemas, not credentials, and embedding a personal access token in a signature is both invalid and insecure. Tokens also expire and are tied to a person, so the endpoint would break when that user leaves or rotates credentials. This does not address how the serving infrastructure authenticates to Unity Catalog resources on behalf of the agent.

  • ✗

    Set the endpoint's environment variable `DATABRICKS_TOKEN` to the workspace owner's token.

    Why it's wrong here

    Hardcoding a workspace owner token in endpoint environment variables is a security anti-pattern and is not how Mosaic AI Agent endpoints authenticate to Unity Catalog. The owner token is over-privileged, non-auditable per-request, and will expire, causing outages. Databricks expects endpoints to use managed service principal credentials so that access can be governed and audited through Unity Catalog.

  • ✓

    Attach a serving credential via a Unity Catalog service principal and grant that principal access to the index and table.

    Why this is correct

    Agent endpoints run under a service identity rather than the deploying user's credentials. By configuring a serving credential backed by a Unity Catalog service principal and granting that principal USE CATALOG, SELECT on the table, and access to the Vector Search index, the endpoint can authenticate to those resources at runtime. This is the supported mechanism for agent endpoints to reach governed data securely.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.